Updated
Updated · WIRED · Sep 19
cve.icu Logs 66,401 CVEs as AI Nearly Doubles Last Year's Vulnerability Count
Updated
Updated · WIRED · Sep 19

cve.icu Logs 66,401 CVEs as AI Nearly Doubles Last Year's Vulnerability Count

1 articles · Updated · WIRED · Sep 19

Summary

  • 66,401 CVEs had been recorded by Wednesday, according to cve.icu, versus 33,512 by September 16 last year and 25,000 for all of 2022.
  • AI-assisted bug hunting is driving the surge: Microsoft has patched 974 CVEs so far this month, Oracle issued 1,448 patches in July versus 309 a year earlier, and Chrome shipped 1,072 fixes across two June releases.
  • Researchers say the jump reflects more known flaws rather than necessarily more underlying software weakness, but it is straining understaffed security teams and open-source maintainers who must triage and fix them.
  • The bigger risk is remediation lag—defenders and users may not patch fast enough while attackers also use AI to find exploitable bugs, widening the window for cyberattacks.
  • Experts say AI is still helping both sides for now, but discovery scales with compute far faster than remediation scales with people.

Insights

If an AI model discovers thousands of zero-day bugs overnight, who wins the race to exploit or patch them first?
Could the massive flood of AI-generated vulnerability alerts actually make our software less secure by completely overwhelming human defenders?

Machine-Speed Threats: The 2026 CVE Boom, AI-on-AI Attacks, and the Collapse of Traditional Vulnerability Management

Overview

In 2026, the surge in CVE disclosures was driven by the deployment of autonomous AI discovery agents like Claude Mythos and GPT-5.4-Cyber, which enabled rapid identification of vulnerabilities across major software. This led to a sharp increase in reported bugs, such as Mozilla’s 271 Firefox fixes, overwhelming human defenders and causing alert fatigue. The National Vulnerability Database could not keep up, halting universal enrichment and breaking traditional compliance workflows. As attackers exploited vulnerabilities faster than patches could be released, organizations shifted to continuous exposure management and adopted AI-native defensive platforms, using contextual prioritization to reduce alert noise and speed up remediation.

...